CVE-2025-26385Disclosure

LOWCVSS 9.5 · CRITICAL

Exploit discussion active in current signal (3 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Johnson Controls Metasys component listed below have Improper Neutralization of Special Elements used in a Command (Command Injection) Vulnerability . Successful exploitation of this vulnerability could allow remote SQL execution This issue affects  * Metasys: Application and Data Server (ADS) installed with SQL Express deployed as part of the Metasys 14.1 and prior installation,  * Extended Application and Data Server (ADX) installed with SQL Express deployed as part of the Metasys 14.1 installation,  * LCS8500 or NAE8500 installed with SQL Express deployed as part of the Metasys installation Releases 12.0 through 14.1,  * System Configuration Tool (SCT) installed with SQL Express deployed as part of the SCT installation 17.1 and prior,  * Controller Configuration Tool (CCT) installed with SQL Express deployed as part of the CCT installation 17.0 and prior.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 7 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 7 signals
  • Disclosure: 5 classified signals
  • Peaked at 3 mentions on most recent observed day (2026-02-02)
  • 7 total mentions across 3 days

Deep dive

Activity timeline7 mentions / 3d
01223Mentions · 2026-01-30: 2Mentions · 2026-02-01: 2Mentions · 2026-02-02: 3PoC Mentioned / Linked · 2026-01-30: 1Patch / Workaround · 2026-02-01: 1Patch / Workaround · 2026-02-02: 2Technical Details · 2026-01-30: 2Technical Details · 2026-02-01: 2Technical Details · 2026-02-02: 301-3002-0102-02
Signal classification2 categories
Disclosure
571.4%
Patch
228.6%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-01-302
Disclosure2
2026-02-012
Disclosure2
2026-02-023
Disclosure1Patch2
Full discourse7 posts
  • CCB Alert@CCBalert
    Patch

    Warning: Critical vulnerability in #Johnson Controls (Metasys SQL Express) allows remote command injection leading to arbitrary SQL execution. #CVE-2025-26385 CVSS: 9.5. Mitigations available at: https://tyco.widen.net/s/crtwxjjcgm/jci-psa-2026-02. #RCE! #Patch #Patch #Patch

    Post summary

    A critical remote command injection vulnerability (CVE‑2025‑26385) in Johnson Controls Metasys SQL Express, with a CVSS score of 9.5, is disclosed and mitigations are available via the provided link.

    01021401
    7.2K followersView on X
  • ThreatSynop@ThreatSynop
    Disclosure

    🚨 Critical Johnson Controls ICS Flaw (CVE-2025-26385) Enables Unauthenticated Remote SQL Injection (CVSS 10.0) A critical unauthenticated SQL injection vulnerability (CVE-2025-26385, CVSS 10.0) impacts multiple Johnson Controls ICS products (ADS/ADX, LCS8500, NAE8500, SCT, CCT), enabling remote attackers to run arbitrary SQL commands and potentially alter/delete/exfiltrate sensitive data. While CISA reported no known public exploitation as of the Jan 27, 2026 advisory, the exposure risk and critical-infrastructure footprint make rapid mitigation (isolation/segmentation, patching, VPN-hardening) urgent. 🎯 Target: Global/Industrial Control Systems #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://cybersecuritynews.com/johnson-controls-products-vulnerabilities/

    Post summary

    A critical unauthenticated SQL injection (CVE‑2025‑26385) in Johnson Controls industrial control systems has been disclosed, with a CVSS score of 10.0 and recommended mitigations such as isolation, patching, and VPN hardening. No public exploitation has been reported yet.

    0001190
    192 followersView on X
  • The Daily Tech Feed@dailytechonx
    Disclosure

    Critical SQL injection vulnerability (CVE-2025-26385) found in Johnson Controls products. Immediate action required to protect critical infrastructure. https://thedailytechfeed.com/critical-sql-injection-vulnerability-in-johnson-controls-products-threatens-global-infrastructure-security/ #Hacking #Vulnerability #CVE #Exploit #Database #Security #Infrastructure #Threat #Protection #Risk #Breach #Mitigation #Patch #Alert #Network #Systems #Software #Update #Cyber #Safety

    Post summary

    The post announces a critical SQL injection vulnerability (CVE-2025-26385) in Johnson Controls products and urges immediate protection measures for critical infrastructure.

    0000061
    238 followersView on X
  • VaultEdge IT Solutions@VaultEdgeIT
    Patch

    ⚠️ Critical Johnson Controls Vulnerability Critical SQL injection (CVE-2025-26385) hits Johnson Controls products. Remote attackers can steal or alter data. CISA urges isolation & patching. 🔗 https://cybersecuritynews.com/johnson-controls-products-vulnerabilities/ #CyberSecurity #ICS #SQLInjection #CISA #JohnsonControls https://t.co/rb3Q7aUuai

    Post summary

    Johnson Controls products are vulnerable to a critical SQL injection (CVE-2025-26385); CISA recommends isolation and patching.

    0000057
    36 followersView on X
  • 趣テクノロジー@omomuki_tech
    Disclosure

    ジョンソンコントロールズ社の複数の産業用制御システム製品において、極めて重大なSQLインジェクションの脆弱性(CVE-2025-26385)が報告されました。この脆弱性の深刻度を示すCVSS v3スコアは、最高値である「10.0」と評価されており、これは影響を受けるインフラにとって最大レベルのリスクが存在することを示しています。 この問題は、コマンドインジェクションで利用される特殊な要素が、システム内で適切に無害化処理されていないことが原因で発生します。この欠陥を悪用されると、遠隔の第三者がシステムに対して不正なSQLコマンドを実行し、データベースを操作することが可能になるリモート攻撃の危険性があります。 #セキュリティ #脆弱性 #SQLインジェクション https://cybersecuritynews.com/johnson-controls-products-vulnerabilities/

    Post summary

    Johnson Controls’ industrial control products have a critical SQL injection flaw (CVE‑2025‑26385) with a CVSS score of 10.0, stemming from unsanitized inputs that could allow remote attackers to execute arbitrary SQL commands.

    0000096
    238 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-26385 Johnson Controls Metasys component listed below have Improper Neutralization of Special Elements used in a Command (Command Injection) Vulnerability . Successful exp… https://www.cve.org/CVERecord?id=CVE-2025-26385

    Post summary

    The post announces CVE-2025-26385 as a command injection vulnerability affecting Johnson Controls Metasys components, providing a link to the CVE record for further details.

    00000217
    56.5K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2025-26385: Metasys product command injectio... Command injection in Johnson Controls Metasys BMS enables unauthenticated remote SQL execution - prime target for later... https://zerodaysignal.com/vulnerability/CVE-2025-26385 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The text announces CVE‑2025‑26385, detailing a command injection flaw in Johnson Controls Metasys BMS that permits unauthenticated remote SQL execution, and links to a source likely providing further information.

    0000080
    132 followersView on X

Explore more